The scoring model

Every risk is scored on two five-point scales. The score is likelihood multiplied by impact, so it runs from 1 to 25. The same bands drive the colours on the heatmap, the score in the register and the readiness check for critical risks.

Scale12345
LikelihoodRareUnlikelyPossibleLikelyAlmost certain
ImpactNegligibleMinorModerateMajorSevere
BandScoreShown as
Low1-6Green cell and score
Medium7-11Amber
High12-16Orange
Critical17-25Red; Prepare for Audit checks that every critical risk has a mitigation plan

Inherent and residual risk

Each risk record keeps two assessments with their own fields: the inherent risk before treatment (inherentLikelihood, inherentImpact, inherentScore) and the residual risk after treatment (residualLikelihood, residualImpact, residualScore). The residual score stays empty until you assess it, and the form only saves both residual values together, so a half-filled assessment cannot slip into the register.

In the register every row shows the inherent score with the residual score next to it (for example 20 → 6), the owner, the status and the chosen treatment.

An interactive 5×5 heatmap

  • Switch the heatmap between inherent and residual with one toggle.
  • Each cell counts the active risks at that likelihood and impact. Active means every status except Mitigated, so accepted and transferred risks stay visible.
  • Click a cell to filter the register to exactly those risks; click again to clear it.
  • In residual mode the caption tells you how many active risks have no residual score yet, so gaps in your assessment are visible instead of silently missing.
  • Next to the heatmap, a status breakdown (open, mitigating, mitigated, accepted, transferred) doubles as a filter.

Treatment, status and deadlines

Treatment options follow ISO 27005: mitigate (reduce likelihood or impact), accept (live with it, documented), transfer (insurance or a third party) or avoid (stop the activity). Status is tracked separately: open, mitigating, mitigated, accepted or transferred.

  • A mitigation plan of up to 4,000 characters and a mitigation deadline per risk.
  • Deadlines show as due soon or overdue in the register until the risk is mitigated, accepted or transferred.
  • Sort by score, by deadline or by owner, and search across title, description, owner, mitigation and acceptance rationale.

Risk acceptance with approver and rationale

Accepting a risk, either by setting the status to Accepted or by choosing the Accept treatment, requires a written rationale. The server refuses the change without one. Dazr then records acceptedBy and acceptedAt itself, from the signed-in admin who saved it: the browser cannot set or backdate those fields. If the risk later moves away from Accepted, the acceptance stamp is cleared, so an old signature never covers a new decision.

The risk modal shows the result in plain words: Accepted by name@company.eu on 12 September 2026.

Owners, roles and history

  • Risk owner (ownerEmail) is separate from the person who entered the risk (createdBy), as ISO 27001 clause 6.1.3 expects.
  • Owners and admins edit the register; members and external auditors can open every risk read-only.
  • History: every change appends an entry with who and when, up to 200 revisions per risk, so rescoring over the years stays traceable.
  • The workspace activity log records each risk.created, risk.updated (including the status change from and to) and risk.deleted event.
  • DPIAs: a risk in a DPIA can point to a register risk. The risk shows which DPIAs reference it, and deleting it warns you first. The DPIA PDF prints the linked risk with its score, residual score and status.
  • Statement of Applicability: "Required by risk assessment" is one of the inclusion reasons per control.
  • Prepare for Audit checks that the register is populated and that every critical risk has a mitigation plan.
  • Export: the risk register is one of the Excel and CSV exports, from Basic.
  • Auditors see the register in their own read-only portal (Pro and Enterprise).
  • REST API and webhooks (Enterprise): list and read risks, filter by status or minimum score, and receive risk.created and risk.updated events in your own tools.